# How to use the new certbot apache v 0.21

**URL:** <https://community.letsencrypt.org/t/how-to-use-the-new-certbot-apache-v-0-21/50797>\
**Category:** Server\
**Created:** [January 18, 2018, 7:23pm UTC](https://community.letsencrypt.org/t/how-to-use-the-new-certbot-apache-v-0-21/50797 "2018-01-18T19:23:05Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 18, 2018, 7:59pm UTC](https://community.letsencrypt.org/t/how-to-use-the-new-certbot-apache-v-0-21/50797/2 "2018-01-18T19:59:48Z")

</div>

> [@jepe](#):
>
> now that you’ve made it, could we get some quick and brief documentation on how to use certbot now with apache?

Depends on how you've installed `certbot` in the first place.

> [@jepe](#):
>
> apt upgrade, for example, does not work in Debian – as mentioned in p4c’s “Question about release and update”

Thats unfortunately a Debian "thing". Debian isn't known for their "up to date" repository. A possible solution might be using the `certbot-auto` (more on that later).

> [@jepe](#):
>
> and what differences are between using webroot and the apache plugin…

Depends which version of the Apache plugin you're refering to 😉 The `webroot` plugin purely is an "authenticator": it's only function is to authorise a FQDN, so Let's Encrypt will issue a certificate for it. It uses the `http-01` challenge. It will _only_ validate your domain, so `certbot` can get the certificate. It won't change anything on your webserver.  
The `apache` plugin however, is an authenticator plugin _as wel as_ an **installer** plugin: it can use a challenge (before version 0.21 the now disabled `tls-sni-01` challenge, with 0.21 and newer the `http-01`challenge) to verify your FQDN (the authenticator part), but it will _also_ modify your webserver configuration, so your site is instantly TLS secured!

As I already said in the [Question about release and update - #3 by Osiris](https://community.letsencrypt.org/t/question-about-release-and-update/50764/3) thread, you can combine the apache installer with the webroot plugin so you can use the `http-01` challenge with `certbot` version \<0.21.

You can read more about the decision on disabeling the `tls-sni-01` challenge here: [TLS-SNI challenges disabled for most new issuance](https://community.letsencrypt.org/t/tls-sni-challenges-disabled-for-most-new-issuance/50316)

You can read more about the solution here, including the use of `certbot-auto`: [Solution: Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA](https://community.letsencrypt.org/t/solution-client-with-the-currently-selected-authenticator-does-not-support-any-combination-of-challenges-that-will-satisfy-the-ca/49983)

---

_[View the full topic](https://community.letsencrypt.org/t/how-to-use-the-new-certbot-apache-v-0-21/50797)._
